Hammer POST /api/login and watch the per-IP window. The fixed
server allows 5 attempts per 60 seconds and checks the limit before the password —
so the 6th try is 429, even with the right password. Advance the clock to age
attempts out. Nothing is sent anywhere; the limiter is computed here.
t = 0s
— no request yet —